{"id":623956,"date":"2026-01-05T09:00:28","date_gmt":"2026-01-05T07:00:28","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=623956"},"modified":"2026-01-05T09:26:44","modified_gmt":"2026-01-05T07:26:44","slug":"hacker-rescues-south-african-pharmacy-from-cyber-attack","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/623956-hacker-rescues-south-african-pharmacy-from-cyber-attack.html","title":{"rendered":"Hacker rescues South African pharmacy from cyber attack"},"content":{"rendered":"\n<p>An independent family-owned pharmacy in Cape Town was recently spared a devastating start to the year thanks to the diligence of cybersecurity forensic investigator Bruce Malaudzi.<\/p>\n\n\n\n<p>Malaudzi had stumbled upon something extremely rare \u2014 a vulnerable server in the midst of suffering a ransomware attack.<\/p>\n\n\n\n<p>Like spotting a Gaboon viper under a pile of leaves that is busy digesting its recently caught prey, he had discovered the system as the malware was infecting it.<\/p>\n\n\n\n<p>\u201cPart of my job is threat hunting,\u201d Malaudzi told MyBroadband. \u201cWhile hunting for threats through Shodan, I came across a Windows server that was directly accessible to the Internet.\u201d<\/p>\n\n\n\n<p>Shodan is a search engine of Internet-connected devices. Often referred to as the search engine for hackers, it lets users query openly available information about any device with a public IP address.<\/p>\n\n\n\n<p>Malaudzi found a server which Shodan reported was vulnerable to a five-year-old remote code execution vulnerability called <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2020-0796\">CVE-2020-0796<\/a>.<\/p>\n\n\n\n<p>The vulnerability exists in unpatched versions of Microsoft Server Message Block 3.1.1 (SMBv3), the file-sharing protocol used by Windows.<\/p>\n\n\n\n<p>Worse still, Windows file sharing was enabled on the server\u2019s root drives with no password set for the root account.<\/p>\n\n\n\n<p>Malaudzi said he first discovered the vulnerable system during the day on Friday, but there were no signs then that it was infected with ransomware.<\/p>\n\n\n\n<p>In fact, he initially dismissed the server as a honeypot \u2014&nbsp; a decoy system designed to attract and trap cyber attackers.<\/p>\n\n\n\n<p>However, when Malaudzi returned to the server later, he found that some of the file names had changed, with the extension \u201c.want_to_cry\u201d appended to many of them.<\/p>\n\n\n\n<p>A text file containing the ransom note, called \u201c!want_to_cry.txt\u201d, was also placed in a subfolder on the file system demanding $600 (R10,135) for a decryption key.<\/p>\n\n\n\n<p>Malaudzi saw file names changing before his eyes as he traversed the system, further indicating that the ransomware was busy running its encryption routine at that very moment.<\/p>\n\n\n\n<p>Working as quickly as he could, Malaudzi searched through the system to find information about the attack and its target, in the hopes of warning the victim.<\/p>\n\n\n\n<p>He found invoice files that had not yet been encrypted, which led him to the name of the business being targeted \u2014 Constantia Pharmacy, located on Spaanschemat River Road in Cape Town.<\/p>\n\n\n\n<p>Other files and folders on the system also suggested that he was looking at a server built to manage a pharmacy, including the name \u201cRxWin\u201d and a database file with \u201cPharm\u201d in its name.<\/p>\n\n\n\n<p>By this point, it was long after hours. Malaudzi wrote an email explaining the situation to MyBroadband, sending it at 04:00 on Saturday, 3 January 2026.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Mounting a rescue<\/h2>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"907\" height=\"650\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/01\/ConstantiaPharmacy-ProPharm-ransomware.png\" alt=\"\" class=\"wp-image-623958\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/01\/ConstantiaPharmacy-ProPharm-ransomware.png 907w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/01\/ConstantiaPharmacy-ProPharm-ransomware-558x400.png 558w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/01\/ConstantiaPharmacy-ProPharm-ransomware-768x550.png 768w\" sizes=\"(max-width: 907px) 100vw, 907px\" \/><figcaption class=\"wp-element-caption\">The information on Shodan about Constantia Pharmacy&#8217;s exposed Windows-based PropPharm RxWin server<\/figcaption><\/figure>\n\n\n\n<p>MyBroadband saw Malaudzi\u2019s email just after 07:00 on Saturday and immediately began verifying his information to contact the pharmacy.<\/p>\n\n\n\n<p>Unfortunately, there was no answer at the pharmacy\u2019s publicly available telephone numbers at 07:24, but we called back at 08:30 when it opened.<\/p>\n\n\n\n<p>After convincing the pharmacist on duty that we were not scammers, we were put in contact with Tessa Wood, the daughter of Noel Wood, who founded the Constantia Pharmacy in 1968.<\/p>\n\n\n\n<p>Wood asked us to call the company that supplies its pharmacy management system, ProPharm, to relay the necessary information directly.<\/p>\n\n\n\n<p>ProPharm, which is owned by the ComputAssist Group, develops the RxWin and RxPRO pharmacy management systems.<\/p>\n\n\n\n<p>To its credit, ProPharm took immediate action, helping to rescue its customer\u2019s data and avoid a costly outage due to the ransomware attack.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Want_to_cry <em>modus operandi<\/em><\/h2>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1072\" height=\"335\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/01\/want_to_cry-ransom-note-redacted.png\" alt=\"\" class=\"wp-image-623959\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/01\/want_to_cry-ransom-note-redacted.png 1072w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/01\/want_to_cry-ransom-note-redacted-600x188.png 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/01\/want_to_cry-ransom-note-redacted-768x240.png 768w\" sizes=\"(max-width: 1072px) 100vw, 1072px\" \/><figcaption class=\"wp-element-caption\">Want_to_cry ransom note<\/figcaption><\/figure>\n\n\n\n<p>Little is known about the group behind Want_to_cry. However, Quick Heal Technologies\u2019 enterprise security arm, Seqrite, <a href=\"https:\/\/www.seqrite.com\/blog\/wanttocry-ransomware-smb-vulnerability\/\">believes<\/a> the gang has been active since December 2023.<\/p>\n\n\n\n<p>The Internet is also littered with reports from self-hosting hobbyists and other individual users who found their personal file servers infected with the ransomware.<\/p>\n\n\n\n<p>According to Seqrite, the group uses brute force attacks against exposed systems to compromise servers with weak passwords or default credentials.<\/p>\n\n\n\n<p>Once access is gained, the ransomware remotely encrypts publicly exposed network drives and network-attached storage devices. The attacker leaves behind a ransom note containing details about payment.<\/p>\n\n\n\n<p>The group does not appear to have a leak site on either the regular clear web or dark web. Therefore, it purely tries to extort money by locking people out of their files.<\/p>\n\n\n\n<p>MyBroadband asked ProPharm and ComputAssist for comment about the attack and why the SMB shares of Constantia Pharmacy\u2019s RxWin server were publicly accessible with no root password set.<\/p>\n\n\n\n<p>Neither company responded by publication. This article will be updated with their statement should they provide feedback.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>An independent family-owned pharmacy in Cape Town was recently spared a devastating start to the year thanks to the diligence of cybersecurity forensic investigator Bruce Malaudzi.<\/p>\n","protected":false},"author":15,"featured_media":623957,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[102734,102737,102735,102739,102736,35095,102738,102733],"class_list":["post-623956","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-bruce-malaudzi","tag-computassist-group","tag-constantia-pharmacy","tag-noel-wood","tag-propharm","tag-shodan","tag-tessa-wood","tag-want_to_cry"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/623956"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=623956"}],"version-history":[{"count":5,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/623956\/revisions"}],"predecessor-version":[{"id":623987,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/623956\/revisions\/623987"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/623957"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=623956"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=623956"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=623956"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}